| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vvpj-8cmc-gx39 | PickleScan's pkgutil.resolve_name has a universal blocklist bypass |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 18 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.system, builtins.exec, or subprocess.call to achieve remote code execution. | |
| Title | picklescan - Universal Blocklist Bypass via pkgutil.resolve_name | |
| First Time appeared |
Mmaitre314
Mmaitre314 picklescan |
|
| Weaknesses | CWE-183 | |
| CPEs | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mmaitre314
Mmaitre314 picklescan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-18T15:23:36.077Z
Reserved: 2026-03-03T16:11:38.661Z
Link: CVE-2026-3490
Updated: 2026-06-18T15:22:54.944Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T21:15:03Z
Github GHSA